Overview
Own and evolve security for production and cloud environments, focusing on network and infrastructure security. Lead secure architecture, controls, reviews, and risk mitigation across cloud and operational teams.
What you'll do
- Design and improve network segmentation, WAF controls, egress filtering, and remediation sequencing.
- Review cloud environments for exposure, identity, logging, network, and secrets-handling gaps.
- Monitor the external attack surface through DNS, certificate transparency, scanning, and ASM tooling.
- Detect configuration drift and assign ownership for discovered assets.
- Partner with engineering and operations teams on secure architecture and change management.
- Coach teams through security reviews, consultations, and targeted training.
- Identify risks and determine mitigation strategies.
What you'll need
- Proven security subject-matter expertise guiding end-to-end secure system design.
- Experience with network architecture, segmentation, and production firewall or IDS-IPS platforms.
- Experience reviewing Azure permissions and configurations, with working knowledge of GCP and on-premises components.
- Experience with attack-surface discovery, external scanning, and continuous monitoring.
- Ability to lead cybersecurity defense architecture and enterprise security posture management.
- Strong communication skills with technical and non-technical audiences.
Nice to have
- Security certifications such as CISSP, GIAC, or CCNP Security.
- Working knowledge of Google Cloud Platform.
- Experience with DSPM or cloud-native data security controls.
- Cloudflare WAF hardening and tuning experience.
Details
- Remote position for residents of Estonia.
- Full-remote work with on-demand coworking access.
Read the full description and apply on the company’s own careers page.